Documentation
What HCM Lens does, what to upload, how the analysis works, and how your data is handled.
Overview
HCM Lens turns your SAP HCM authorization exports into an explainable, prioritized access-risk ranking with audit-ready evidence.
Internal audit, GRC / security teams, and SAP authorization owners.
Scores access risk transparently — every score is explained by its rules.
Prioritized risks (score + reason) and audit-ready exports.
Required SAP exports
The supported flow is SAP-native: export your SAP tables (XLSX or CSV, with their technical headers) and upload them as-is — no manual consolidation.
The role/access tables describing users, their role assignments, and the authorizations each role grants (plus role and transaction texts for readability).
An optional usage export (user × transaction × date) enables unused-permission detection with real evidence. Without it, that check is safely skipped.
Each file is read through a strict allowlist of expected columns; anything not listed — including any password-hash columns — is never read, parsed or stored. Files are processed in memory and discarded.
How the analysis works
- 1 Upload your SAP exports (optional usage file included).
- 2 Preflight — each file is validated against its expected structure.
- 3 Dry-run — preview what would be imported and scored; nothing is persisted.
- 4 Upload & scoring — confirm to persist an immutable run and compute the ranking.
- 5 Review — browse prioritized users and roles; every score is explained.
- 6 Compare runs — see how risk changed between two analyses (A/B).
- 7 Export — download audit-ready rankings.
Security & privacy
- No raw retention: files are processed in memory and never written to disk at the app layer.
- Pseudonymization: SAP user identifiers are keyed-HMAC pseudonymized, and encrypted at rest where stored.
- Tenant isolation: one organization can never see another organization’s data.
- Value-free diagnostics: warnings and errors never echo SAP ids, cell values or filenames.
- No SAP secrets accepted: password hashes and similar columns are rejected by design.
- Invitation-only access: there is no public sign-up; accounts are provisioned manually.
Demo & access
Request a demo by email. Access is provisioned manually by invitation.
Request demo → we review → we provision a demo/trial organization and send an invitation → production access follows an agreement. There is no self-service registration.
Request a demoFAQ
No. You upload standard SAP table exports; nothing is installed in your SAP system.
Only with a lawful basis. Processing real employee data requires internal authorization and an applicable data processing agreement (DPA); for evaluation, use synthetic or anonymized exports. In all cases files are processed in memory and discarded, and identifiers are pseudonymized.
They are parsed in memory and not retained at the application layer.
XLSX and CSV exports with technical SAP headers.
Yes — compare any two analyses (A/B) to see how access risk evolved.
No. Access is invitation-only, provisioned manually after a demo request.